System and method for information security threat disruption via a border gateway
Summary by NHIP
Border Gateway Threat Disruption System
The method receives first and second alerts from monitoring devices regarding detected information security attacks on downstream computing devices. An intermediate upstream gateway disrupts the threat, triggering automatic mitigation from a database or forwarding data to a central command center for further action.
Claim Score by NHIP
Abstract
A system and method for disrupting an information security threat that constitutes an attack on a computer asset in a computer network is provided. The provided system and method disrupts this information security threat after the attack on the computer asset has been detected by at least one of the monitoring devices on the affected computer network. An intermediate upstream gateway of the affected computer network is then utilized to disrupt this information security threat. As the detected attack is being disrupted, a mitigation action will be automatically initiated if a mitigation action associated with the attack is stored in the system's database; else information about the attack will be sent to a central command centre for further assessment. At the central command centre, a mitigating action will be further developed and executed to address the intention of the attack.

Term
8.6 yearsleft in the term
Expires 19 May 2035, including 62 days of term adjustment.
- Priority and filed
- Granted
- Today
- Expires
18 claims: 3 independent, 15 dependent
- 1A method for disrupting an information security attack on at least one computing device of a plurality of computing devices in a managed computer network, the method comprising:receiving using an event manager system, a first alert and a second alert from at least one monitoring device of a plurality of monitoring devices in the managed computer network and connected to the plurality of computing devices, wherein the event manager system is linked to the plurality of computing devices via a communicative connection of the event manager system and the plurality of monitoring devices, wherein each of the plurality of computing devices has its network activity monitored by at least one of the plurality of monitoring devices for an information security attack and each of the plurality of computing devices is located downstream of at least one of the plurality of monitoring devices, wherein the event manager system is within the managed computer network;the at least one monitoring device generating the first alert in response to a first detection by a first network security device within the at least one monitoring device of an information security attack and generating the second alert in response to a second detection by a second network security device within the at least one monitoring device of an information security attack, and wherein the first alert and the second alert both include an Internet Protocol address of a source that initiated the detected information security attack on the at least one computing device and an identity of an intermediate upstream gateway of the managed computer network through which the attack passed, whereby the attack on the at least one computing device passed through the intermediate upstream gateway and at least one other gateway in the managed computer network and wherein the intermediate upstream gateway comprises a network node on the managed computer network that is located upstream of each of the plurality of monitoring devices and the at least one other gateway in the managed computer network;determining by the event manager system operating parameters of the intermediate upstream gateway based on the identity of the intermediate upstream gateway through which the attack passed included in the first alert and the second alert by comparing the identity against a gateway database;determining if the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is to be disrupted using the event manager system based on the first and second alerts received from the at least one monitoring device, wherein the event manager system compares the first alert and the second alert to determine whether the two alerts are similar, whereby determining that the two alerts are similar indicates that the information security attack of the first detection and the information security attack of the second detection are the same information security attack which is a real attack and the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is therefore to be disrupted;if the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is to be disrupted, generating a first set of instructions based on the operating parameters using the event manager system and transmitting via a network outside the managed computer network, the first set of instructions from the event manager system only to the intermediate upstream gateway, wherein the first set of instructions only instruct the intermediate upstream gateway to add the IP address of the source that initiated the information security attack to an access control list of the intermediate upstream gateway;generating a second set of instructions based on the operating parameters using the event manager system and transmitting via a network outside the managed computer network, the second set of instructions from the event manager system to only the intermediate upstream gateway after a first period of time has lapsed, wherein the second set of instructions only instruct the intermediate upstream gateway to remove the IP address of the source that initiated the information security attack from the access control list of the intermediate upstream gateway;determining, during the first period of time, if a new mitigation action is to be created to address the first alert and the second alert based on a security alert database using the event manager system;and if the new mitigation action is to be created to address the first alert and the second alert, transmitting the first alert and the second alert from the event manager system to a command center which resides outside the managed computer network.
- 7A system for disrupting an information security attack on at least one computing device of a plurality of computing devices in a managed computer network comprising:an event manager system including: a processing unit;and a non-transitory media readable by the processing unit, the media storing instructions that when executed by the processing unit, cause the processing unit to: receive a first alert and a second alert from at least one monitoring device of a plurality of monitoring devices in the managed computer network and connected to the plurality of computing devices, wherein the event manager system is linked to the plurality of computing devices via a communicative connection of the event manager system and the plurality of monitoring devices, wherein each of the plurality of computing devices has its network activity monitored by at least one of the plurality of monitoring devices for an information security attack and each of the plurality of computing devices is located downstream of at least one of the plurality of monitoring devices, wherein the event manager system is within the managed computer network;the at least one monitoring device generating the first alert in response to a first detection by a first network security device within the at least one monitoring device of an information security attack and generating the second alert in response to a second detection by a second network security device within the at least one monitoring device of an information security attack, and wherein the first alert and the second alert both include an Internet Protocol address of a source that initiated the detected information security attack on the at least one computing device and an identity of an intermediate upstream gateway of the managed computer network through which the attack passed, whereby the attack on the at least one computing device passed through the intermediate upstream gateway and at least one other gateway in the managed computer network and wherein the intermediate upstream gateway comprises a network node on the managed computer network that is located upstream of each of the plurality of monitoring devices and the at least one other gateway in the managed computer network;determine operating parameters of the intermediate upstream gateway based on the identity of the intermediate upstream gateway through which the attack passed included in the first alert and the second alert by comparing the identity against a gateway database;determine, using the first and second alerts, if the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is to be disrupted, wherein the event manager system compares the first alert and the second alert to determine whether the two alerts are similar, whereby determining that the two alerts are similar indicates that the information security attack of the first detection and the information security attack of the second detection are the same information security attack which is a real attack and the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is therefore to be disrupted;if the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is to be disrupted, to generate a first set of instructions based on the operating parameters and to transmit the first set of instructions via a network outside the managed computer network, to only the intermediate upstream gateway, wherein the first set of instructions only instruct the intermediate upstream gateway to add the IP address of the source that initiated the information security attack to an access control list of the intermediate upstream gateway;generate a second set of instructions based on the operating parameters and to transmit via a network outside the managed computer network, the second set of instructions to only the intermediate upstream gateway after a first period of time has lapsed, wherein the second set of instructions only instruct the intermediate upstream gateway to remove the IP address of the source that initiated the information security attack from the access control list of the intermediate upstream gateway;determine, during the first period of time, if a new mitigation action is to be created to address the first alert and the second alert based on a security alert database;and if the new mitigation action is to be created to address the first alert and the second alert, to transmit the first alert and the second alert to a command center which resides outside the managed computer network.
- 13Broadest claimClaim Score 10, narrow(NHIP)An event manager system in a computer network system for disrupting an information security attack on at least one computing device of a plurality of computing devices in a managed computer network comprising:circuitry configured to receive a first alert and a second alert from at least one monitoring device of a plurality of monitoring devices in the managed computer network and connected to the plurality of computing devices, wherein the event manager system is linked to the plurality of computing devices via a communicative connection between the plurality of computing devices and the event manager system, wherein each of the plurality of computing devices has its network activity monitored by at least one of the plurality of monitoring devices for an information security attack and each of the plurality of computing devices is located downstream of at least one of the plurality of monitoring devices, wherein the event manage system is within the managed computer network;the at least one monitoring device generating the first alert in response to a first detection by a first network security device within the at least one monitoring device of an information security attack and generating the second alert in response to a second detection by a second network security device within the at least one monitoring device of an information security attack, and wherein the first alert and the second alert both include an Internet Protocol address of a source that initiated the information security attack on the at least one computing device and an identity of an intermediate upstream gateway of the managed computer network through which the attack passed, whereby the attack on the at least one computing device passed through the intermediate upstream gateway and at least one other gateway in the managed computer network and wherein the intermediate upstream gateway comprises a network node on the managed computer network that is located upstream of each of the plurality of monitoring devices and the at least one other gateway in the managed computer network;circuitry configured to determine operating parameters of the intermediate upstream gateway based on the identity of the intermediate upstream gateway through which the attack passed included in the first alert and the second alert by comparing the identity against a gateway database;circuitry configured to determine if the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is to be disrupted based on the first and second alerts, wherein the event manager system compares the first alert and the second alert to determine whether the two alerts are similar, whereby determining that the two alerts are similar indicates that the information security attack of the first detection and the information security attack of the second detection are the same information security attack which is a real attack and the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is therefore to be disrupted;circuitry configured to generate a first set of instructions based on the operating parameters and to transmit via a network outside the managed computer network the first set of instructions to only the intermediate upstream gateway, if it is determined that the Internet Protocol address of the source that initiated the information security attack on the at least one computing device is to be disrupted, wherein the first set of instructions only instruct the intermediate upstream gateway to add the IP address of the source that initiated the information security attack to an access control list of the intermediate upstream gateway;circuitry configured to generate a second set of instructions based on the operating parameters and to transmit via a network outside the managed computer network the second set of instructions to only the intermediate upstream gateway after a first period of time has lapsed, wherein the second set of instructions only instruct the intermediate upstream gateway to remove the IP address of the source that initiated the information security attack from the access control list of the intermediate upstream gateway;circuitry configured to determine, during the first period of time, if a new mitigation action is to be created to address the first alert and the second alert based on a security alert database;and circuitry configured to transmit the first alert and the second alert to a command center which resides outside the managed computer network, if it is determined that the new mitigation action is to be created to address the first alert and the second alert.
Independent claims3
73 paragraphs in 6 sections, as filed
CROSS REFERENCE TO RELATED APPLICATIONS
This application is a national stage application of PCT Application No. PCT/SG2015/050040 filed on Mar. 18, 2015, the disclosure of which is hereby incorporated by reference in its entirety.
FIELD OF THE INVENTION
This invention relates to a system and method for disrupting an information security threat that constitutes an attack on a computer asset in a computer network. More particularly, this invention relates to a system and method for disrupting this information security threat after the attack on the computer asset has been detected by at least one of the monitoring devices on the affected computer network. An intermediate upstream gateway of the affected computer network is then utilized to disrupt this information security threat. The detected security threat is disrupted at the intermediate upstream gateway for a period of time by automatically blocking the Internet Protocol (IP) address of the source of the attack from transmitting further data to the computer network. After this period of time has lapsed, the IP address of the source will be automatically unblocked. As the detected attack is being disrupted, a mitigation action will be automatically initiated if a mitigation action associated with the attack is stored in the system's database; else information about the attack will be sent to a central command centre for further assessment. At the central command centre, a mitigating action will be further developed and executed to address the intention of the attack.
SUMMARY OF THE PRIOR ART
The management of a computer network's security is becoming more challenging as computer networks grow in size and as computer networks become an integral part of most organizations' daily operations. As the number of computers within an organization's computer network is ever increasing, there is a higher likelihood of computer network misconfiguration and mismanagement thereby allowing attackers to gain unauthorized access and steal information from the computer network. Due to the advancements in computing technology, attacks on computer networks are becoming increasingly sophisticated, making it difficult for existing security management tools to respond to these attacks in a real time manner. Furthermore, if an attack on a computer network is stopped or repelled, without continuous vigilance and monitoring, the computer network will still not be immune to similar attacks as attackers will naturally be compelled to attempt new attack methodologies to gain unauthorized access to the same secured computer networks. Therefore, maintaining and managing the network security of a computer network is an ever evolving complex problem.
Attacks on a computer asset within a computer network may occur in the form of wiretapping, network sniffing, viruses, malwares, IP spoofing, Trojan horses, Denial of Service attacks or any other such similar methods. Furthermore, such information security attacks may be sent in the form of multiple data packets across the IP networks as the original larger data packets would have been fragmented into multiple smaller data packets as they are transmitted. The multiple smaller data packets will then recombine once all the data packets arrive at their intended target. If some of these smaller data packets do not arrive at their intended target, this would result in an incomplete final data packet that would typically be rejected by a computing device as such incomplete data packets would be treated as corrupted data packets.
The main objective of such attack methodologies would be to damage computer assets within the computer network resulting in the computer network's users losing access to information contained within the computer network and/or to steal confidential information contained within the servers or computers located within the computer network. Irrespective of the intent of the attack, such attacks have to be quickly stopped and repelled upstream before lasting damage occurs.
Of particular concern to network administrators is the speed at which an attack on a computer network can take place and spread through the network of computers. Most computer networks utilize routers, gateways and/or firewalls to prevent such attacks from accessing computers located behind the firewall. A firewall is typically used to secure a local area computer network from users that are located outside the local area network. The firewall does this by monitoring the incoming and outgoing traffic from the local area network. The firewall does this by checking, and frequently labelling messages sent to or from users outside the local trusted area network.
However, the problem faced by existing systems and methods is that known attacks and their associated mitigating actions are only periodically loaded into the firewalls. Thus, a new passive or active attack may potentially be undetectable. By the time network administrators react to these new attacks, the damage would already have been done long ago. For the above reasons, those skilled in the art are constantly striving to come up with a system and method to manage the security of a computer network in an efficient and high speed manner.
SUMMARY OF THE INVENTION
The above and other problems are solved and an advance in the art is made by systems and methods provided by embodiments in accordance with the invention. A first advantage of embodiments of systems and methods in accordance with the invention is that once information security alerts are generated by monitoring devices on the network, a potential security threat that constitutes an attack on a computer asset in a computer network is immediately disrupted by adding the Internet Protocol (IP) address of the source that generated the threat to an access control list of an intermediate upstream gateway of the computer network for a period of time. During this period of time, the threat can be further analysed and a future mitigation enhanced action can be inferred and executed. This is to ensure that similar security threats are rapidly and effectively mitigated with less human intervention. Furthermore, the act of disrupting the potential security threat may in itself be the mitigation action to address the attack. By disrupting the transmission of data packets of the potential security threat, the system is in actual fact breaking down the attack before the attack is able to properly form at its intended target.
A second advantage of embodiments of systems and methods in accordance with the invention is that as a hybrid communication means may be utilized to transmit instructions to a gateway of the computer network, this ensures that appropriate instructions may be transmitted to the gateway even if conventional telecommunication networks are jammed or compromised.
A third advantage of embodiments of systems and methods in accordance with the invention is that the invention is able to handle multiple threats simultaneously as the system would automatically block ingress and egress network threats by adding the security threat's source IP address into access control lists of the intermediate upstream gateways thereby disrupting these threats immediately while allowing sufficient time for additional further mitigating actions to be executed, if necessary.
A fourth advantage of embodiments of systems and methods in accordance with the invention is that the invention is able to disrupt the intermediate gateway through which the information security threat passed regardless of the brand, type, version or model of this upstream gateway. A fifth advantage of embodiments of systems and methods in accordance with the invention is that a potential security threat that constitutes an attack on a computer asset in a computer network is immediately disrupted by adding the Internet Protocol (IP) address of the source that generated the threat to the access control lists of all gateways of the computer network that are located upstream of computer assets in the computer network for a period of time.
The above advantages are provided by embodiments of a system in accordance with the invention operating in the following manner. The system has a processing unit and a non-transitory media readable by the processing unit. The media is configured to store instructions that when executed by the processing unit, cause the processing unit to receive and to process a first alert and a second alert from a monitoring device on the network. The first alert and the second alert both include an Internet Protocol address of a source that initiated the information security attack on the computer network and an identity of the gateway through which the attack passed. The instructions when executed by the processing unit also directs the processing unit to determine if the Internet Protocol address of the source that initiated the information security attack on the computer network is to be disrupted and generate a first set of instructions and transmit the first set of instructions to the gateway through which the attack passed through. The first set of instructions instructs the gateway to add the IP addresses of the source of attack that initiated the information security attack to an access control list of the gateway.
The instructions when executed by the processing unit also directs the processing unit to generate a second set of instructions and to transmit the second set of instructions to the gateway of the computer network after a first period of time has lapsed, wherein the second set of instructions instructs the gateway to remove the IP address of the source that initiated the information security attack from the access control list of the gateway. Further, the instructions when executed by the processing unit also directs the processing unit to determine, during the first period of time, if a new mitigation action is to be created to address the first alert and the second alert based on a security alert database; and if a new mitigation action is to be created to address the first alert and the second alert, to transmit the first alert and the second alert to a command centre.
In accordance with embodiments of the invention, the instructions to transmit the first set of instructions to the gateway of the computer network comprises instructions for directing the processing unit to determine if the first set of instructions can be transmitted to the gateway of the computer network using a telecommunication network, and if it is determined that the first set of instructions cannot be transmitted using the telecommunication network, to transmit the first set of instructions to the gateway of the computer network using an out-of-band network.
In accordance with embodiments of the invention, the instructions to generate the first set of instructions comprises instructions for directing the processing unit to use the identity of the gateway to select an associated instruction set from a gateway database, and to compile the first set of instructions using the selected instruction set.
In accordance with embodiments of the invention, the instructions to transmit the second set of instructions to the gateway of the computer network comprises instructions for directing the processing unit to determine if the second set of instructions can be transmitted to the gateway of the computer network using a telecommunication network, and if it is determined that the second set of instructions cannot be transmitted using the telecommunication network, to transmit the second set of instructions to the gateway of the computer network using an out-of-band network.
In accordance with embodiments of the invention, the instructions to generate the second set of instructions comprises instructions for directing the processing unit to use the identity of the gateway to select an associated instruction set from a gateway database, and to compile the second set of instructions using the selected instruction set.
In accordance with further embodiments of the invention, the gateway comprises a network node on the computer network that is located upstream of the monitoring device. In accordance with yet another further embodiment of the invention, the gateway comprises a first network node on the computer network and a second network node on the computer network wherein the second network node is located upstream of the first network node, and the first network node is located upstream of the monitoring device. In accordance with still yet another further embodiment of the invention, the gateway comprises all network nodes on the computer network that are located upstream of the monitoring device.
In accordance with embodiments of the invention, the instructions to transmit the first alert and the second alert to the command centre comprises instructions for directing the processing unit to determine if the first alert and the second alert can be transmitted to the command centre directly using a telecommunication network, and if it is determined that the first alert and the second alert cannot be transmitted directly using the telecommunication network, to transmit the first alert and the second alert to the gateway of the computer network using an out-of-band network, wherein the first alert and second alert is then transmitted from the gateway to the command centre using the telecommunication network.
In accordance with embodiments of the invention, the instructions to determine if the Internet Protocol address of the source that initiated the information security attack on the computer network is to be disrupted comprises instructions for directing the processing unit to determine if the first alert correlates with the second alert; and if the first alert correlates with the second alert, to confirm that the Internet Protocol address of the source that initiated the information security attack is to be disrupted. In accordance with further embodiments of the invention, the media further includes instructions that when executed by the processing unit direct the processing unit to add the new mitigation action created by the command centre to address the first alert and the second alert into the security alert database.
In accordance with yet another embodiment of the invention, the system has a processing unit and a non-transitory media readable by the processing unit. The media is configured to store instructions that when executed by the processing unit, cause the processing unit to receive and process an alert from a monitoring device on the network, wherein the alert includes an Internet Protocol address of a source that initiated the information security attack on the computer network and an identity of a gateway through which the attack passed.
The instructions further cause the processing unit to generate a first set of instructions and to transmit the first set of instructions to the gateway through which the attack passed, wherein the first set of instructions instruct the gateway to add the IP address of the source that initiated the information security attack to an access control list of the gateway, and to transmit a second set of instructions to the gateway through which the attack passed after a first period of time has lapsed, wherein the second set of instructions instruct the gateway to remove the IP address of the source that initiated the information security attack from the access control list of the gateway. Further, the instructions when executed by the processing unit also directs the processing unit to determine, during the first period of time, if a new mitigation action is to be created to address the alert based on a security alert database, and if a new mitigation action is to be created to address the alert, transmitting the alert to a command centre.
BRIEF DESCRIPTION OF THE DRAWINGS
The above advantages and features in accordance with this invention are described in the following detailed description and are shown in the following drawings:
<figref idref="DRAWINGS">FIG. 1</figref> illustrating a network diagram of components that make up a network security management system for disrupting an attack in accordance with an embodiment of the invention;
<figref idref="DRAWINGS">FIG. 2</figref> illustrating a timing diagram of an attack on a computer network that is being managed by a security management system in accordance with an embodiment of the invention;
<figref idref="DRAWINGS">FIG. 3</figref> illustrating a timing diagram of an attack on a computer network that is being disrupted by a security management system in accordance with embodiments of the invention;
<figref idref="DRAWINGS">FIG. 4</figref> illustrating a flow diagram of a process for disrupting an attack on a computer network in accordance with embodiments of the invention;
<figref idref="DRAWINGS">FIG. 5</figref> illustrating a flow diagram of another process for disrupting an attack on a computer network in accordance with embodiments of the invention;
<figref idref="DRAWINGS">FIG. 6</figref> illustrating a flow diagram of a process for determining if an information security threat is to be disrupted in accordance with embodiments of the invention; and
<figref idref="DRAWINGS">FIG. 7</figref> illustrating a block diagram representative of processing systems providing embodiments in accordance with embodiments of the invention.
DETAILED DESCRIPTION
This invention relates to a system and method for disrupting an information security threat that constitutes an attack on a computer asset in a computer network, wherein this information security threat is disrupted after the attack on the computer asset has been detected by at least one of the monitoring devices on the affected computer network. An intermediate upstream gateway of the affected computer network is then utilized to disrupt this information security threat. The detected security threat is disrupted at the intermediate upstream gateway for a period of time by automatically blocking the Internet Protocol (IP) address of the source of the attack from transmitting further data to the computer network. After this period of time has lapsed, the IP address of the source will be automatically unblocked. As the detected attack is being disrupted, a mitigation action will be automatically initiated if a mitigation action associated with the attack is stored in the system's database; else information about the attack will be sent to a central command centre for further assessment. At the central command centre, a mitigating action will be further developed and executed to address the intention of the attack.
<figref idref="DRAWINGS">FIG. 1</figref> illustrates network under management <b>100</b> that includes modules and devices that execute processes to provide a method and system for disrupting information security threats originating from computing devices <b>125</b>, <b>126</b> that target computer assets within network <b>100</b> in accordance with embodiments of the invention. As illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, network under management <b>100</b> includes computer assets such as computing devices <b>105</b>, <b>106</b> and <b>107</b>. Computing devices <b>105</b>, <b>106</b>, and <b>107</b> may include any type of computing device and may comprise, but are not limited to, smart phones, laptops, tablets, computers, servers, workstations, and so on. One skilled in the art will recognize that computing devices <b>105</b>, <b>106</b>, and <b>107</b> are only provided as an example and other types of devices with displays, processors, non-transitory media for storing instructions, alphanumeric input means and pointer manipulating means may be used without departing from this invention. Further, although <figref idref="DRAWINGS">FIG. 1</figref> illustrates that only three computing devices are provided within the network <b>100</b>, in actual fact, many more computing devices may be provided within the network <b>100</b> without departing from this invention.
As illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, computing devices <b>105</b>, <b>106</b> and <b>107</b> all connect to network <b>120</b> via intermediate upstream gateway <b>118</b>. Computing devices <b>105</b>, <b>106</b> and <b>107</b> communicatively connect to gateway <b>118</b> either via wired means, wireless means or a combination of both. Wired means may include a wired network such as a wide area network (WAN) or a local area network (LAN), while wireless means includes connections established via Radio Frequency (RF) signals, infrared signals, or any other means of wireless transmissions. Gateway <b>118</b> is a node on network <b>100</b> which serves as an access point from network <b>120</b> to network <b>100</b>. In other words, gateway <b>118</b> provides an entry point for data traveling into network <b>100</b> from network <b>120</b> and conversely, provides an exit point for data traveling in the other direction, from network <b>100</b> to network <b>120</b>. As such, in the embodiment illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, if computing devices <b>125</b>, <b>126</b> were to initiate an information security attack on computing devices that are located within network <b>100</b>, these information security attacks would first have to first pass through gateway <b>118</b>.
Gateway <b>118</b> may include any network node that is able to route internet traffic from any number of computing devices located behind the gateway to computing devices located on external networks. Such network nodes include, but are not limited to, devices that utilize border gateway protocols, DSL routers, cable routers, VLAN, bridges, switches, etc. As for network <b>120</b>, network <b>120</b> is a communications network, such as the Internet, that allows computing devices and/or processing systems to communicate with one another either through wired means, wireless means or a combination of both. Although <figref idref="DRAWINGS">FIG. 1</figref> only illustrates that network <b>100</b> comprises of only gateway <b>118</b>, one skilled in the art will recognize that network <b>100</b> may have any number of gateways without departing from this invention.
Computing devices in network <b>100</b> may be indirectly or directly connected to gateway <b>118</b>. <figref idref="DRAWINGS">FIG. 1</figref> illustrates computing devices <b>106</b> and <b>107</b> that are indirectly connected to gateway <b>118</b> while computing device <b>105</b> is illustrated as being directly connected to gateway <b>118</b>. It should be noted that computing devices <b>105</b>, <b>106</b> and <b>107</b> are communicatively connected to their respective monitoring devices either via wired means, wireless means or a combination of both. As illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, computing devices <b>106</b> and <b>107</b> reside behind both monitoring devices <b>117</b> and <b>116</b> and this means that any data transmitted to gateway <b>118</b> from computing devices <b>106</b>, <b>107</b> will have to first pass through both monitoring devices <b>117</b> and <b>116</b>. Similarly, any data transmitted from gateway <b>118</b> to computing devices <b>106</b>, <b>107</b> will also have to pass through both monitoring devices <b>117</b> and <b>116</b> before the data is received by computing devices <b>106</b>, <b>107</b>. As such, any attempted information security attacks on either one of computing devices <b>106</b> or <b>107</b> may be easily detected by monitoring devices <b>116</b> and <b>117</b>. Unlike computing devices <b>106</b>, <b>107</b>, as computing device <b>105</b> is directly connected to gateway <b>105</b>, any information security attacks on computing device <b>105</b> may not be instantaneously detected by the system as all data transmission takes place directly between computing device <b>105</b> and gateway <b>118</b>. To address this flaw, there will be a direct connection between computing device <b>105</b> and monitoring device <b>115</b> whereby monitoring device <b>115</b> will sporadically check the status of computing device <b>105</b> to ensure that computing device <b>105</b> has not been compromised by an information security attack.
Although <figref idref="DRAWINGS">FIG. 1</figref> illustrates that only gateway <b>118</b> is located upstream of monitoring devices <b>115</b>, <b>116</b>, <b>117</b>, any number of other gateways belonging to network <b>100</b> may be provided upstream of these monitoring devices without departing from this invention. For example, in yet another embodiment of the invention, gateway <b>118</b> may comprise of two network nodes. In particular, gateway <b>118</b> may comprise of a first network node and a second network node whereby the second network node is located upstream of the first network node, and the first network node is located upstream of monitoring devices <b>115</b>, <b>116</b>, <b>117</b>. This means that data transmitted from network <b>120</b> towards computing devices <b>105</b>, <b>106</b>, <b>107</b> would have to first pass through the first network node, and the second network node before the data may be received by computing devices <b>105</b>, <b>106</b>, <b>107</b>. One skilled in the art will recognize that gateway <b>118</b> is not limited to just two network nodes and may comprise of any number of network nodes belonging to network <b>100</b> that are located upstream of the monitoring devices in network <b>100</b>. Further, from hereon, when reference is made in the description to a gateway, one skilled in the art will recognize that the referenced gateway may comprise of either a single network node or a plurality of network nodes without departing from this invention.
Monitoring devices <b>115</b>, <b>116</b>, <b>117</b> are network security devices that monitor a computer network's activities for malicious activities and may include any type of device or computer module that is able to identify malicious activity, log information about this activity, trigger and subsequently transmit an alert when such activity has been detected. Furthermore, when logging information about the detected malicious activity, these monitoring devices are also able to resolve, log and transmit the IP address of the source that is initiating the attack together with the IP address and identity of the network's gateway via which the attack passed through to access computing devices within network <b>100</b>. Such network security devices may include, but are not limited to, hardware or software firewalls, antivirus software programs installed within computer modules, intrusion detection systems and/or intrusion prevention systems. The attacks that may be detected by these network security devices include, but are not limited to, TCP and UDP attacks or strings of malformed emails targeted at exploiting administrator access, the propagation of an unknown variant of a computer virus, rejected login requests and/or various types of login violations. In accordance with embodiments of the invention, monitoring devices <b>115</b>, <b>116</b> and <b>117</b> may comprise of one network security device, or two network security devices or any number of security devices without departing from this invention. For example, in the illustration shown in <figref idref="DRAWINGS">FIG. 1</figref>, monitoring device <b>116</b> may comprise of two network security devices, that is a firewall and an intrusion detection and prevention system or in accordance with another embodiment of the invention, monitoring device <b>116</b> may comprise of one network security device, which is a firewall while monitoring device <b>117</b> may comprise of another network security device as well, which is an intrusion detection and prevention system. One skilled in the art will recognize that various configurations of computing devices and monitoring devices may be used without departing from this invention and are not limited only to the configurations shown in <figref idref="DRAWINGS">FIG. 1</figref>.
Monitoring devices <b>115</b>, <b>116</b> and <b>117</b> are all communicatively connected to event manager <b>110</b> either via wired means, wireless means or a combination of both. Event manager <b>110</b> includes various computer modules for carrying out various functions such as, but not limited to, a computing module for receiving and processing alerts from monitoring devices, a computing module for storing received alerts in a database provided within event manager <b>110</b>, a computing module for transmitting a received alert to a global command centre using a telecommunications network, a computing module for communicating with a gateway via an out-of-band network, and a transceiver module for receiving/transmitting data from/to the Internet. In addition to the above, event manager <b>110</b> may also include a computing module for determining the IP address or identity of the gateway through which an information security network attack entered network <b>100</b>. This computing module may also obtain from the IP address or identity of the gateway the operating parameters of this gateway such as the brand, model and/or version of the gateway. This is so that once event manager <b>110</b> has ascertained the IP address and/or identity of the gateway and subsequently the operating parameters of the network's gateway, by comparing this information with data stored within a database about various types of gateways available, event manager <b>110</b> will then be able to select from the database an appropriate instruction set associated with the identified network's gateway. The selected instruction set will then be used to compile instructions that are to be sent to the gateway.
Event manager <b>110</b> may be communicatively connected to gateway <b>118</b> via a telecommunications network or via an out-of-band network. If data is to be transmitted from event manager <b>110</b> to gateway <b>118</b> via a telecommunications network, event manager <b>110</b> will first transmit this data to network <b>120</b> either via wired means, wireless means or a combination of both. The data will then be transmitted from network <b>120</b> to gateway <b>118</b> via a telecommunication interface on gateway <b>118</b>. Telecommunication networks that may be utilized to transmit data between event manager <b>110</b> and gateway <b>118</b> may include, but are not limited to, a TCP/IP data network or an optical transport network. In the event the telecommunication interface of gateway <b>118</b> is disrupted or blocked, an out-of-band network may be utilized to transmit data from event manager <b>110</b> to gateway <b>118</b>. When an out-of-band network is utilized, data will initially be transmitted from event manager <b>110</b> to gateway <b>118</b> via internet <b>120</b> using Secure Shell (SSH), Secure Sockets Layer (SSL), Telnet and RS-232 protocols. The data will then be transmitted from network <b>120</b> to an out-of-band interface provided at gateway <b>118</b>. The out-of-band interface is usually built into gateway <b>118</b> and may be used to receive instructions to configure an access control list of gateway <b>118</b>. In accordance with an embodiment of the invention, the out-of-band interface at gateway <b>118</b> may comprise standard RS-232 serial ports. The RS-232 serial port at gateway <b>118</b> may be used to receive instructions to change root parameters within gateway <b>118</b>, as well as receive instructions to modify other administrative and reporting functions, such as the gateway's access control list.
When a new information security attack is detected, a new mitigation action has to be developed and executed to address this new threat. The development of the new mitigation action typically takes place at global command centre <b>130</b>. Global command centre <b>130</b> may be a secure data centre that has consultants or analysts for analysing information security attacks and threats. In the embodiment illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, global command centre <b>130</b> may receive alerts or various other transmissions from event manager <b>110</b> via network <b>120</b>. Upon receiving these alerts, personnel at global command centre <b>130</b> will then analyse and develop appropriate mitigation actions to address these alerts. The appropriate mitigation actions may then be transmitted to event manager <b>110</b> using network <b>120</b>.
<figref idref="DRAWINGS">FIG. 2</figref> illustrates a timing diagram of an information security threat on the computer network of system <b>100</b> as initiated by untrusted computing device <b>125</b> in accordance with an embodiment of the invention. As previously illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, computing device <b>125</b> is an untrusted device that is initiating information security threats targeting computing devices <b>105</b>, <b>106</b>, <b>107</b> on network <b>100</b> through gateway <b>118</b>. In particular, at step <b>201</b><i>a</i>, untrusted computing device <b>125</b> transmits an information security network attack targeting computing device <b>105</b>. The network attack from computing device <b>125</b> passes through gateway <b>118</b> at step <b>201</b><i>b </i>and is detected by a first monitoring module, network security device or mechanism within monitoring device <b>115</b> at step <b>201</b><i>c</i>. Immediately, upon detecting the network attack from computing device <b>125</b>, the first network security device within monitoring device <b>115</b> will transmit a first alert to event manager <b>110</b>. This takes place at step <b>201</b><i>d</i>. If monitoring device <b>115</b> is provided with a second monitoring mechanism, network security device or module, a second alert will also be sent to event manager <b>110</b> once the second network security device detects the similar attack. This occurs at step <b>201</b><i>e</i>. In accordance with embodiments of the invention, the first network security device within monitoring device <b>115</b> may be a firewall and the second network security device within monitoring device <b>115</b> may be an intrusion detection system or vice versa.
In addition to alerting event manager <b>110</b> about the network attack, monitoring device <b>115</b> will also resolve the IP address of the source of the network attack and will also obtain the identity and IP address of the gateway through which the attack passed through. All this information will then be provided together with the alert that is transmitted to event manager <b>110</b>.
Similarly, a network attack from computing device <b>125</b> that targets computing devices <b>106</b>, <b>107</b> will pass through gateway <b>118</b> at step <b>201</b><i>b </i>and will be detected by a first monitoring module, network security device or mechanism within monitoring device <b>116</b> at step <b>202</b><i>c</i>. Immediately, upon detecting the network attack from computing device <b>125</b>, the first network security device within monitoring device <b>116</b> will transmit a first alert to event manager <b>110</b>. This takes place at step <b>202</b><i>d</i>. In the event that monitoring device <b>116</b> is also provided with a second monitoring mechanism, network security device or module, a second alert will be triggered and sent to event manager <b>110</b> once the second network security device detects the above mentioned attack. This occurs at step <b>202</b><i>e. </i>
With reference to <figref idref="DRAWINGS">FIG. 3</figref>, after event manager <b>110</b> has received the first alert from monitoring device <b>115</b>; event manager <b>110</b> will analyse and process the information contained within the first alert to obtain the identity of the gateway through which the information security network attack entered network <b>100</b>. Using this identity, event manager <b>110</b> will then determine the operating parameters of the gateway, which in this example is gateway <b>118</b>, such as the brand, model and/or version of the gateway. This is so that once event manager <b>110</b> has ascertained the brand, model and/or version of the gateway, based on information stored within a database about various types of gateways available, event manager <b>110</b> will then be able to select from the database an appropriate instruction set associated with the identified gateway.
After event manager <b>110</b> has selected an instruction set associated with the identified gateway, event manager <b>110</b> will use the selected instruction set to compile a set of instructions to instruct the gateway to add the IP address of the source that initiated the information security attack to an access control list of the gateway. If the instructions are transmitted using a telecommunications network, this set of instructions will first be compiled using standard telecommunication protocols and transmitted to network <b>120</b> at step <b>301</b><i>a </i>and then subsequently transmitted to gateway <b>118</b> at step <b>301</b><i>b</i>. A telecommunication interface at gateway <b>118</b> will receive the instructions and add the IP address of the source that initiated the information security attack to an access control list of gateway <b>118</b> thereby effectively blocking all data transmissions from the source of the attack to network <b>100</b>.
After step <b>301</b><i>b</i>, event manager <b>110</b> will determine whether a new mitigation action is to be created for the alert that was received from monitoring device <b>115</b>. Event manager <b>110</b> does this by trying to find a match between the received alert with a list of alerts stored within a security alert database. If event manager <b>110</b> is able to find a match from the list of stored alerts, a mitigating action associated with the stored alert will be retrieved and will be carried out by event manager <b>110</b>. Alternatively, if event manager <b>110</b> is unable to match the received alert with a stored alert in the security alert database, the alert will then be transmitted from event manager <b>110</b> to global command centre <b>130</b> at step <b>301</b><i>c</i>. At global command centre <b>130</b>, computer analysts and consultants will analyse the received alert and will create a mitigating action to address the network attack. The mitigating action will then be executed by global command centre <b>130</b> accordingly. After the attack has been repelled, the mitigating action that was executed to address the attack will be added into the security alert database at event manager <b>110</b> along with details of the associated network attack. This is so that if such information security attacks occur in the future, the corresponding mitigating action may be retrieved from the security alert database thereby negating the need to communicate with global command centre <b>130</b>.
After a first period of time has lapsed, event manager <b>110</b> will use the previously selected instruction set to compile a set of instructions to instruct the gateway to remove the IP address of the source that initiated the information security attack from the access control list of the gateway. As the instructions were previously transmitted using a telecommunications network, this set of instructions will similarly be compiled using standard telecommunication protocols and then be transmitted to network <b>120</b> at step <b>301</b><i>d </i>and subsequently transmitted to gateway <b>118</b> at step <b>301</b><i>e</i>. The telecommunication interface at gateway <b>118</b> will similarly receive the instructions and remove the IP address of the source that initiated the information security attack from the access control list of gateway <b>118</b> thereby effectively unblocking all data transmissions from the source of the attack to network <b>100</b>. In accordance with embodiments of the invention, the first period of time may be any period of time ranging from 1 minute to 60 minutes.
In accordance with another embodiment of the invention, if event manager <b>110</b> determines that the telecommunications network is jammed, disrupted and may not be used, event manager <b>110</b> will transmit the instructions using an out-of-band network. An appropriate out-of-band protocol will first be used to compile the set of instructions. The set of instructions will then be transmitted to network <b>120</b> at step <b>302</b><i>a </i>and then subsequently transmitted to gateway <b>118</b> at step <b>302</b><i>b</i>. An out-of-band interface at gateway <b>118</b> will receive the instructions and add the IP address of the source that initiated the information security attack to an access control list of gateway <b>118</b> thereby effectively blocking all data transmissions from the source of the attack to network <b>100</b>. Similarly as discussed above, after step <b>302</b><i>b</i>, event manager <b>110</b> will determine whether a new mitigation action is to be created for the alert that was received from monitoring device <b>115</b>. If a new mitigation action is to be created, the alert will then be transmitted from event manager <b>110</b> to global command centre <b>130</b> at step <b>302</b><i>c </i>whereby a mitigation action to address the network attack will be developed and executed. Alternatively, if a new mitigation action does not need to be created, the previously created mitigation action will be executed by event manager <b>110</b> automatically.
After a first period of time has lapsed, event manager <b>110</b> will use the previously selected instruction set to compile a set of instructions to instruct the gateway to remove the IP address of the source that initiated the information security attack from the access control list of the gateway. As the instructions were previously transmitted using the out-of-band network, the appropriate out-of-band protocol will similarly be used to compile this set of instructions. The set of instructions will then be transmitted to network <b>120</b> at step <b>302</b><i>d </i>and then subsequently transmitted to gateway <b>118</b> at step <b>302</b><i>e</i>. An out-of-band interface at gateway <b>118</b> will receive the new instructions and remove the IP address of the source that initiated the information security attack from the access control list of gateway <b>118</b> thereby unblocking all data transmissions from the source of the attack to network <b>100</b>.
In accordance with another embodiment of the invention, before step <b>301</b><i>a </i>takes place, which is before event manager <b>110</b> generates a set of instructions to instruct the gateway to add the IP address of the source that initiated the information security attack to the access control list of the gateway, event manager <b>110</b> will first determine if the first alert has been correlated with a second alert. In other words, event manager <b>110</b> will determine whether the first alert issued by monitoring device <b>115</b> is in relation to a real attack or a false alarm by comparing details of the first alert with details of a second alert. One skilled in the art will recognize that the first and second alerts may be issued by a single monitoring device, e.g. monitoring device <b>115</b>, or may be issued by two separate monitoring devices, e.g. a first alert that is issued by monitoring device <b>115</b> and a second alert that is issued by monitoring device <b>116</b>. If event manager <b>110</b> correlates the first and second alerts, this indicates that the attack is a real attack and not a false alarm and as such, the IP address of the source of the attack should be disrupted from transmitting further data to network <b>100</b>.
For example, with reference to <figref idref="DRAWINGS">FIGS. 2 and 3</figref>, after event manager <b>110</b> receives a first alert from monitoring device <b>115</b> at step <b>201</b><i>d </i>and a second alert from monitoring device <b>115</b> at step <b>201</b><i>e</i>; event manager <b>110</b> compares these two alerts to determine whether these two alerts are similar. If the two alerts are similar, this indicates to event manager <b>110</b> that the attack detected by the two modules within monitoring device <b>115</b> is a real attack and that the attack should be disrupted. Event manager <b>110</b> then caries out steps <b>301</b><i>a</i>-<b>301</b><i>e </i>or <b>302</b><i>a</i>-<b>302</b><i>e </i>as discussed above.
In order to provide such a system or method, a process is needed for disrupting information security threats or attacks on a computer network using the network's gateway. The following description and <figref idref="DRAWINGS">FIGS. 4-6</figref> describe embodiments of processes that provide such a disruption process in accordance with this invention.
<figref idref="DRAWINGS">FIG. 4</figref> illustrates process <b>400</b> that is performed by a computer system in a computing device for disrupting an information security attack on a computer network in accordance with embodiments of the invention. Process <b>400</b> begins in step <b>405</b> by receiving an alert from a first monitoring device. In accordance with embodiments of the invention, the first monitoring device will typically trigger an alert upon detection of an information security threat or a network anomaly. An IP address of the source of the network attack and the identity and IP address of the gateway through which the attack passed through will be captured by the first monitoring device and be included together with the alert.
In embodiments of the invention, once process <b>400</b> receives the alert, process <b>400</b> will analyse the information contained within the first alert to determine the operating parameters of the gateway through which the information security network attack entered the network, such as the brand, model and/or version of the gateway. This is so that once process <b>400</b> has ascertained the brand, model and/or version of the gateway, based on information stored within a database about various types of gateways available, process <b>400</b> will then be able to select from the database an appropriate instruction set associated with the identified gateway.
After process <b>400</b> has selected an instruction set associated with the identified gateway, process <b>400</b> will use the selected instruction set to compile a set of instructions to instruct the identified gateway to add the IP address of the source that initiated the information security attack to an access control list of the gateway. This instruction set is then transmitted to the identified gateway. This takes place at step <b>410</b>.
At step <b>415</b>, process <b>400</b> determines whether a first period of time has lapsed. If the first period of time has not lapsed, process <b>400</b> will then proceed to step <b>420</b>. At step <b>420</b>, process <b>400</b> determines whether the received alert is to be transmitted to a command centre. If the alert is to be transmitted to the command centre, process <b>400</b> progresses to step <b>425</b>. Process <b>400</b> then proceeds to transmit the alert to the command centre at step <b>425</b> and once this is done, process <b>400</b> proceeds to step <b>415</b>.
Back at step <b>415</b>, process <b>400</b> determines whether the first period of time has lapsed and if not, process <b>400</b> progresses to step <b>420</b>. As the alert no longer needs to be transmitted, process <b>400</b> now progresses to step <b>415</b> and steps <b>415</b>-<b>420</b> repeats until the first period of time has passed.
After the first period of time has lapsed, process <b>400</b> proceeds to step <b>430</b>. At this step, process <b>400</b> will use the previously selected instruction set to compile a set of instructions to instruct the identified gateway to remove the IP address of the source that initiated the information security attack from the access control list of the gateway. This instruction set is then transmitted to the identified gateway. Process <b>400</b> then ends.
In accordance with yet another embodiment of the invention, a process performed by a computer system in a computing device for disrupting an information security attack on a computer network is illustrated in <figref idref="DRAWINGS">FIG. 5</figref>. Process <b>500</b> begins in step <b>505</b> by receiving a first alert and a second alert from a monitoring device. As previously mentioned, a first alert will typically be triggered by a first module within the monitoring device upon detection of a network attack or a network anomaly and a second alert will usually be triggered by a second module within the monitoring device upon detection of a network attack as well. An IP address of the source of the network attack and the identity and IP address of the gateway through which the attack passed through will be included together with the first and second alerts.
Process <b>500</b> will then determine at step <b>510</b> whether the IP address of the source that triggered the first and second alerts is to be blocked or whether the alerts are false alarms. If process <b>500</b> determines that the alerts are correlated, process <b>500</b> will determine that the alerts are related to a real attack and process <b>500</b> will proceed to step <b>515</b>. Else, if the alerts do not correlate, process <b>500</b> will end.
At step <b>515</b>, once process <b>500</b> has determined that the alert are related to a real attack, process <b>500</b> will analyse the information contained within the first and second alerts to determine the operating parameters of the gateway through which the information security network attack entered the network, such as the brand, model and/or version of the gateway. This is so that once process <b>500</b> has ascertained the brand, model and/or version of the gateway, based on information stored within a database about various types of gateways available, process <b>500</b> will then be able to select from the database an appropriate instruction set associated with the identified gateway.
After process <b>500</b> has selected an instruction set associated with the identified gateway, process <b>500</b> will use the selected instruction set to compile a set of instructions to instruct the identified gateway to add the IP address of the source that initiated the information security attack to an access control list of the gateway. This instruction set is then transmitted to the identified gateway. This all still takes place at step <b>515</b>.
At step <b>520</b>, process <b>500</b> determines whether a first period of time has lapsed. If the first period of time has not lapsed, process <b>500</b> will then proceed to step <b>525</b>. At step <b>525</b>, process <b>500</b> determines whether the received alert is to be transmitted to a command centre. If the alert is to be transmitted to the command centre, process <b>500</b> progresses to step <b>530</b>. Process <b>500</b> then proceeds to transmit the alert to the command centre at step <b>530</b> and once this is done, process <b>500</b> proceeds to step <b>520</b>.
Back at step <b>520</b>, process <b>500</b> determines whether the first period of time has lapsed and if not, process <b>500</b> progresses to step <b>525</b>. As the alert no longer needs to be transmitted, process <b>500</b> now progresses to step <b>520</b> and steps <b>520</b>-<b>525</b> repeats until the first period of time has passed.
After the first period of time has lapsed, process <b>500</b> proceeds to step <b>535</b>. At this step, process <b>500</b> will use the previously selected instruction set to compile a set of instructions to instruct the identified gateway to remove the IP address of the source that initiated the information security attack from the access control list of the gateway. This instruction set is then transmitted to the identified gateway. Process <b>500</b> then ends.
<figref idref="DRAWINGS">FIG. 6</figref> illustrates process <b>600</b> that is performed by a computer system in a computing device for determining if the data transmission from the IP address of the source that triggered the alert at the first monitoring device is to be disrupted in accordance with embodiments of the invention. Process <b>600</b> begins at step <b>605</b> by comparing details about the attack as contained within the first and second alerts. At step <b>610</b> if process <b>600</b> determines that both alerts are identical, process <b>600</b> progresses to step <b>620</b>. At step <b>620</b>, process <b>600</b> then issues a confirmation that the source that triggered the alert at the monitoring device is indeed an information security network attack or threat and as such, should be disrupted by the system. Process <b>600</b> then ends.
Returning to step <b>610</b>, if process <b>600</b> determines that the first alert does not match with the second alert, process <b>600</b> will then proceed to step <b>615</b>. At step <b>615</b>, process <b>600</b> then issues a confirmation that the attack is a false alarm and as such, the IP address of the source that triggered the attack is not to be disrupted by the system. Process <b>600</b> then ends.
Processes provided by instructions stored in a non-transitory media are executed by a processing unit in a computer system. For the avoidance of doubt, non-transitory computer-readable media shall be taken to comprise all computer-readable media except for a transitory, propagating signal. A computer system may be provided in one or more computing devices and/or computer servers to provide this invention. The instructions may be stored as firmware, hardware, or software. <figref idref="DRAWINGS">FIG. 7</figref> illustrates an example of such a processing system. Processing system <b>700</b> may be the processing system in the mobile devices and/or servers that execute the instructions to perform the processes for providing a method and/or system in accordance with embodiments of this invention. One skilled in the art will recognize that the exact configuration of each processing system may be different and the exact configuration of the processing system in each mobile device may vary and <figref idref="DRAWINGS">FIG. 7</figref> is given by way of example only.
Processing system <b>700</b> includes Central Processing Unit (CPU) <b>705</b>. CPU <b>705</b> is a processor, microprocessor, or any combination of processors and microprocessors that execute instructions to perform the processes in accordance with the present invention. CPU <b>705</b> connects to memory bus <b>710</b> and Input/Output (I/O) bus <b>715</b>. Memory bus <b>710</b> connects CPU <b>705</b> to memories <b>720</b> and <b>725</b> to transmit data and instructions between memories <b>720</b>, <b>725</b> and CPU <b>705</b>. I/O bus <b>715</b> connects CPU <b>705</b> to peripheral devices to transmit data between CPU <b>705</b> and the peripheral devices. One skilled in the art will recognize that I/O bus <b>715</b> and memory bus <b>710</b> may be combined into one bus or subdivided into many other busses and the exact configuration is left to those skilled in the art.
A non-volatile memory <b>720</b>, such as a Read Only Memory (ROM), is connected to memory bus <b>710</b>. Non-volatile memory <b>720</b> stores instructions and data needed to operate various sub-systems of processing system <b>700</b> and to boot the system at start-up. One skilled in the art will recognize that any number of types of memory may be used to perform this function.
A volatile memory <b>725</b>, such as Random Access Memory (RAM), is also connected to memory bus <b>710</b>. Volatile memory <b>725</b> stores the instructions and data needed by CPU <b>705</b> to perform software instructions for processes such as the processes required for providing a system in accordance with embodiments of this invention. One skilled in the art will recognize that any number of types of memory may be used as volatile memory and the exact type used is left as a design choice to those skilled in the art.
I/O device <b>730</b>, keyboard <b>735</b>, display <b>740</b>, memory <b>745</b>, network device <b>750</b> and any number of other peripheral devices connect to I/O bus <b>715</b> to exchange data with CPU <b>705</b> for use in applications being executed by CPU <b>705</b>. I/O device <b>730</b> is any device that transmits and/or receives data from CPU <b>705</b>. Keyboard <b>735</b> is a specific type of I/O that receives user input and transmits the input to CPU <b>705</b>. Display <b>740</b> receives display data from CPU <b>705</b> and display images on a screen for a user to see. Memory <b>745</b> is a device that transmits and receives data to and from CPU <b>705</b> for storing data to a media. Network device <b>750</b> connects CPU <b>705</b> to a network for transmission of data to and from other processing systems.
The above is a description of embodiments of a system and process in accordance with the present invention as set forth in the following claims. It is envisioned that others may and will design alternatives that fall within the scope of the following claims.
Contents6
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both waysCites: the store holds 58 of 59
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11431758B2 | Cited by | United States of America | Search report |
| US2002166063A1 | Cites | United States of America | Search report |
| US2004030923A1 | Cites | United States of America | Search report |
| US2004103314A1 | Cites | United States of America | Applicant |
| US2005138425A1 | Cites | United States of America | Search report |
| US2005144467A1 | Cites | United States of America | Search report |
| US2005198519A1 | Cites | United States of America | Search report |
| US2006010389A1 | Cites | United States of America | Search report |
| US2006077964A1 | Cites | United States of America | Search report |
| US2006119486A1 | Cites | United States of America | Search report |
| US2006282893A1 | Cites | United States of America | Search report |
| US2008127324A1 | Cites | United States of America | Search report |
| US2008181100A1 | Cites | United States of America | Search report |
| US2010242084A1 | Cites | United States of America | Search report |
| US2010262688A1 | Cites | United States of America | Search report |
| US2012072574A1 | Cites | United States of America | Search report |
| US2013067560A1 | Cites | United States of America | Applicant |
| US2014245439A1 | Cites | United States of America | Search report |
| US2014283030A1 | Cites | United States of America | Search report |
| US2015135316A1 | Cites | United States of America | Search report |
| US2015135317A1 | Cites | United States of America | Search report |
| US2015222652A1 | Cites | United States of America | Search report |
| US2016036837A1 | Cites | United States of America | Search report |
| US7051369B1 | Cites | United States of America | Search report |
| US7434254B1 | Cites | United States of America | Applicant |
| US7610624B1 | Cites | United States of America | Search report |
| US8056130B1 | Cites | United States of America | Applicant |
| US8085681B2 | Cites | United States of America | Search report |
| US8499348B1 | Cites | United States of America | Search report |
| US8528041B1 | Cites | United States of America | Search report |
| US8561187B1 | Cites | United States of America | Search report |
| US8621065B1 | Cites | United States of America | Search report |
| US8832833B2 | Cites | United States of America | Search report |
| US8881281B1 | Cites | United States of America | Search report |
| US8914878B2 | Cites | United States of America | Search report |
| US9118711B2 | Cites | United States of America | Search report |
| US9571511B2 | Cites | United States of America | Search report |
| US20020166063A1 | Cites | United States of America | Search report |
| US20040030923A1 | Cites | United States of America | Search report |
| US20040103314A1 | Cites | United States of America | Applicant |
| US20050138425A1 | Cites | United States of America | Search report |
| US20050144467A1 | Cites | United States of America | Search report |
| US20050198519A1 | Cites | United States of America | Search report |
| US20060010389A1 | Cites | United States of America | Search report |
| US20060077964A1 | Cites | United States of America | Search report |
| US20060119486A1 | Cites | United States of America | Search report |
| US20060282893A1 | Cites | United States of America | Search report |
| US20080127324A1 | Cites | United States of America | Search report |
| US20080181100A1 | Cites | United States of America | Search report |
| US20100242084A1 | Cites | United States of America | Search report |
| US20100262688A1 | Cites | United States of America | Search report |
| US20120072574A1 | Cites | United States of America | Search report |
| US20130067560A1 | Cites | United States of America | Applicant |
| US20140245439A1 | Cites | United States of America | Search report |
| US20140283030A1 | Cites | United States of America | Search report |
| US20150135316A1 | Cites | United States of America | Search report |
| US20150135317A1 | Cites | United States of America | Search report |
| US20150222652A1 | Cites | United States of America | Search report |
| US20160036837A1 | Cites | United States of America | Search report |
| Mujtaba, Muhammad; Nanda, Priyadarsi; He, Xiangjian; “Border Gateway Protocol Anomaly Detection using Failure Quality Control Method”, 11th International Conference on Trust, Security and Privacy in Computing and Communications, IEEE, Jun. 25-27, 2012, pp. 1239-1244. | Non-patent | – | Search report |
| Deshpande, S.; Thottan, M.; Sikdar, B.; “Early Detection of BGP Instabilities Resulting from Internet Worm Attacks”, IEEE Global Telecommunications Conference (GLOBECOM), Nov. 29-Dec. 3, 2004, pp. 2266-2270. | Non-patent | – | Search report |
| International Search Report for International Application No. PCT/SG2015/050040, Search completed Jun. 2, 2015, dated Jun. 2, 2015, 3 Pgs. | Non-patent | – | Applicant |
| International Preliminary Report on Patentability from Australian Patent Office dated May 31, 2017 for relating International Application No. PCT/SG2015/050040. | Non-patent | – | Applicant |
| Extended European Search Report from EPO dated Nov. 24, 2017 for relating European Application No. 15796998.1. | Non-patent | – | Applicant |
| Mujtaba, Muhammad; Nanda, Priyadarsi; He, Xiangjian; “Border Gateway Protocol Anomaly Detection using Failure Quality Control Method”, 11th International Conference on Trust, Security and Privacy in Computing and Communications, IEEE, Jun. 25-27, 2012, pp. 1239-1244. | Non-patent | – | Search report |
| Deshpande, S.; Thottan, M.; Sikdar, B.; “Early Detection of BGP Instabilities Resulting from Internet Worm Attacks”, IEEE Global Telecommunications Conference (GLOBECOM), Nov. 29-Dec. 3, 2004, pp. 2266-2270. | Non-patent | – | Search report |
| International Search Report for International Application No. PCT/SG2015/050040, Search completed Jun. 2, 2015, dated Jun. 2, 2015, 3 Pgs. | Non-patent | – | Applicant |
| International Preliminary Report on Patentability from Australian Patent Office dated May 31, 2017 for relating International Application No. PCT/SG2015/050040. | Non-patent | – | Applicant |
| Extended European Search Report from EPO dated Nov. 24, 2017 for relating European Application No. 15796998.1. | Non-patent | – | Applicant |
15 members in 8 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2015050040 | Singapore | W | |
| 2015050040 | Singapore | W | |
| PCTSG2015050040 | – | – | – |
| WO2015SG50040 | – | – | – |
Members15
| Document | Office | Kind | |
|---|---|---|---|
| CN105765942A | China | A | |
| US2016277436A1 | United States of America | A1 | |
| WO2016148641A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201635182A | Taiwan Province of China | A | |
| SG11201509821SA | Singapore | A | |
| EP3108614A1 | European Patent Office (EPO) | A1 | |
| AU2015387270A1 | Australia | A1 | |
| EP3108614A4 | European Patent Office (EPO) | A4 | |
| CN108183921A | China | A | |
| AU2015387270B2 | Australia | B2 | |
| US10693904B2This record | United States of America | B2 | |
| TWI699666B | Taiwan Province of China | B | |
| MY184710A | Malaysia | A | |
| CN108183921B | China | B | |
| EP3108614B1 | European Patent Office (EPO) | B1 |
134 transactions on the USPTO file
Allowed after 4 non-final rejections, 4 final rejections and 3 RCEs.
- Non-final rejections
- 4
- Final rejections
- 4
- RCEs
- 3
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Email NotificationEML_NTR | EML_NTR | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Response to 312 Amendment (PTO-271)MN271 | MN271 | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Response to Amendment under Rule 312N271 | N271 | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Amendment after Notice of Allowance (Rule 312)AllowedA.NA | A.NA | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| After Final Consideration Program Additional Consideration and/or updated searchAFAC | AFAC | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| PILOT- Request for After Final Consideration ProgramRAFC | RAFC | |
| Response after Final ActionA.NE | A.NE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Applicant Initiated Interview SummaryMEXIA | MEXIA | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Interview Summary- Applicant InitiatedEXIA | EXIA | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Response after Non-Final ActionA... | A... | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| After Final Consideration Program Amendment too ExtensiveAFNE | AFNE | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| PILOT- Request for After Final Consideration ProgramRAFC | RAFC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Applicant Initiated Interview SummaryMEXIA | MEXIA | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Interview Summary- Applicant InitiatedEXIA | EXIA | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. |
22 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: application discontinuationFINAL REJECTION MAILEDSTCB | STCB | |
| Information on status: patent application and granting procedure in generalFINAL REJECTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalDOCKETED NEW CASE - READY FOR EXAMINATIONSTPP | STPP | |
| Information on status: patent application and granting procedure in generalADVISORY ACTION MAILEDSTPP | STPP | |
| AssignmentAS | AS | |
| Information on status: application discontinuationFINAL REJECTION MAILEDSTCB | STCB | |
| Information on status: patent application and granting procedure in generalFINAL REJECTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 10693904
- Publication, DOCDB
- 10693904
- Publication, EPODOC
- US10693904
- Application
- 14893668
- Application, DOCDB
- 201514893668
- Application, EPODOC
- US201514893668
Titles
- English
- System and method for information security threat disruption via a border gateway
Patent term adjustment
- A delay
- +100 daysthe office missed an examination deadline
- Applicant delay
- −38 days
- Net adjustment
- 62 days
Classification
- CPC, 7
- H04L63/1441
- H04L63/101
- H04L41/0631
- H04L63/0236
- H04L63/1466
- H04L63/1416
- H04L63/1475
- IPC, 1
- H04L29 06
- USPC, 1
- 726022000